vciy

CVEs we hold for Netatalk

Records whose assigning authority named Netatalk as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-7837TOCTOU with root privilege in ad_flushNetatalk
CVE-2026-7836hextoint macro uppercase bugNetatalk
CVE-2026-7835Format string argument mismatchNetatalk
CVE-2026-45699Netatalk has Integer Underflow → Stack Buffer Overflow in copydir()netatalk
CVE-2026-45698Netatalk has Integer Underflow → Stack Buffer Overflow in deletedir()netatalk
CVE-2026-44076Shell injection via volume pathNetatalk
CVE-2026-44075Missing break in DSI OpenSessionNetatalk
CVE-2026-44074Bitwise OR of errno valuesNetatalk
CVE-2026-44073seteuid failure ignored in auth modulesNetatalk
CVE-2026-44072system() after failed chdir()Netatalk
CVE-2026-44071FORTIFY_SOURCE disabledNetatalk
CVE-2026-44070Unbounded realloc in charset conversionNetatalk
CVE-2026-44069Integer underflow in volxlateNetatalk
CVE-2026-44068EA path traversal via incomplete sanitizationNetatalk
CVE-2026-44067EA header parsing heap over-readNetatalk
CVE-2026-44066Heap out-of-bounds reads in Spotlight RPC unmarshallingNetatalk
CVE-2026-44065Off-by-two in papd lp_write()Netatalk
CVE-2026-44064ASP session ID out-of-bounds accessNetatalk
CVE-2026-44063LDAP filter injectionNetatalk
CVE-2026-44062Missing o_len bounds check in pull_charset_flags()Netatalk
CVE-2026-44061DES-ECB auth with timing side channelNetatalk
CVE-2026-44060Integer underflow in dsi_writeinit() leads to denial of serviceNetatalk
CVE-2026-44059Non-reentrant privilege toggleNetatalk
CVE-2026-44058Authentication bypass via admin auth userNetatalk
CVE-2026-44057Dead bounds check in Spotlight RPC unmarshallerNetatalk
CVE-2026-44056Stack buffer overflow in desktop.cNetatalk
CVE-2026-44055Bitwise OR logic bug enables shell injectionNetatalk
CVE-2026-44054Predictable afpd session tokenNetatalk
CVE-2026-44053Weak cryptography in DHCAST128 UAMNetatalk
CVE-2026-44052LDAP simple-bind password exposure in log outputNetatalk
CVE-2026-44051Arbitrary file read via attacker-controlled symlink creationNetatalk
CVE-2026-44050Heap buffer overflow in CNID daemon comm_rcv()Netatalk
CVE-2026-44049Out-of-bounds write in convert_charset() null terminationNetatalk
CVE-2026-44048Stack buffer overflow via UCS-2 type confusion in convert_charset()Netatalk
CVE-2026-44047SQL injection in MySQL CNID backendNetatalk
CVE-2022-43634no title heldNetatalk
CVE-2022-23125no title heldNetatalk
CVE-2022-23124no title heldNetatalk
CVE-2022-23123no title heldNetatalk
CVE-2022-23122no title heldNetatalk
CVE-2022-23121no title heldNetatalk
CVE-2022-0194no title heldNetatalk
CVE-2018-1160no title heldNetatalk

43 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.